KIKOMAN · LEGAL
Privacy Policy
This document answers three questions: what we collect about you, what we do with it, and how you delete it. No "including but not limited to … and other information" — where a list can be complete, we made it complete.
The short version
- To register we need one phone number or one email address — your choice. We do not ask for your name, ID number or address. If you buy a paid entitlement, we separately record the order, manual payment-verification and entitlement information.
- You can sign in with a one-time code and may set a password after signing in. The server stores only a password hash, never the plaintext password.
- Points are recorded only against the server account; we do not collect a device fingerprint. The IP address is used only for rate limiting and detecting abuse and attacks, not to create or reset points.
- Optimal packing, animation and result export send the necessary scene data to the server. Optimal-packing results stay in process memory for up to 6 hours; result-export audit metadata is kept for 90 days.
- The primary server is in Hong Kong, China. For email codes, the email address is also sent to Resend in the United States to send the code; sign-in gives this notice and asks for separate consent before requesting a code.
- To delete your account: tap "Delete account" in the app. Your phone number / email is unbound and removed immediately and can be registered again straight away.
Who processes your information
Your personal information is processed by the person below. The law requires us to state this clearly, including a real name and a contact that actually reaches someone:
- Personal information handler
- 罗智予(个人)
- Legal nature
- Individual developer, not a company. There is no corporate entity and no business licence behind this service
- whatsmyweixinid
- Contact email
- l2539527429@gmail.com
- Service covered
- Maxpack (imkikoman.com and imkikoman.com/app)
- Effective date of this version
- 2026-08-21 (version 2026-08-21)
"We" below means that person. The service is currently run by one individual; no other staff can reach your data.
What we collect, why, for how long, and where it lives
This table is the heart of the policy. If it isn't in the table, we don't collect it.
| What | Why | How long | Where |
|---|---|---|---|
| Phone number or email address one of the two at sign-up; you may bind both to one account | To create and identify your account, send sign-in codes, and contact you about the service if needed | While the account exists. Deleted from the database immediately on account deletion; the number/address can then be registered again | Server in Hong Kong, China; for email codes, the email address is also sent to Resend (Resend, Inc.) in the United States |
| Email one-time code stored only as a salted hash | To confirm the sign-in is really you | 5 minutes; cleared once used or expired | Server in Hong Kong, China |
| SMS one-time code | To confirm the sign-in is really you | We never store it — the SMS provider generates and verifies it; it is not in our database at all | At the SMS provider (see section 06) |
| Optional account password the database stores only a salted scrypt hash, never plaintext | To let you sign in with a password, and to set, change or reset it | While the account exists; replaced by a new hash when changed or reset, and cleared on account deletion | Server in Hong Kong, China |
| Session credential only a hash is stored in the database | To keep you signed in without a new code every time | 30 days; invalidated immediately on sign-out or account deletion | Server in Hong Kong, China + a cookie in your browser |
| IP address | Rate limiting and detecting abuse and attacks; it is not used to create or reset points | Kept alongside the corresponding run records and consent records | Server in Hong Kong, China |
| Usage records timestamp, how many items this run had, and which account it belongs to | Point-balance accounting, troubleshooting, capacity planning | Long-term (see the note below the table) | Server in Hong Kong, China |
| Scene data needed for optimal packing, animation and result export including cargo, container, position, dimension and rule data needed to perform the selected feature | To compute optimal packing, generate an animation plan or generate a result file on the server | Raw request details are not written to the database. Optimal-packing results remain in process memory for up to 6 hours and may be evicted earlier. Animation requests and generated plans, and result-export scenes and file contents, are not written to the database or that result cache. Result export separately records audit metadata without scene details for 90 days | The service process on the Hong Kong server; result-export audit metadata in its database |
| Consent records time of consent, the IP at the time, a hash of the browser identifier, and the policy version you agreed to | To evidence that consent was obtained and which version it covered — the law requires us to be able to show this | Long-term; after account deletion no longer linked to your phone number or email | Server in Hong Kong, China |
| Order, manual payment-verification and entitlement records plan, amount, payment channel and reference, verification status and time, entitlement granted and remaining runs | To process orders, check payment or redemption codes, activate and account for paid entitlements, and handle support or disputes | The current server code sets no automatic deletion period; deleting an account does not automatically delete these historical records | Server in Hong Kong, China |
The items marked long-term or with no automatic deletion period are account point-balance and usage counters, consent evidence, and order, payment-verification and entitlement records. Each account receives 10 points, once, on its first valid registration; deleting the counter would incorrectly reset that balance. Consent records show which policy version was accepted, while order and entitlement records account for transactions and entitlements already issued. On account deletion the phone number, email address and password hash are deleted. Historical records may retain the account ID, but the deleted phone number or email can no longer be used to sign in to that account.
What we don't collect
None of the following is collected, and the interface never asks for it:
- Name, national ID number, passport number
- Gender, date of birth, age
- Home or company address, precise location
- Bank-card numbers, online-banking passwords, or WeChat Pay / Alipay payment passwords
- Contacts, photos, SMS messages, call logs
- Biometrics such as face or fingerprint data
We do no profiling, no targeted advertising, and we do not sell or share your information with any third party for their own purposes.
Local JSON / XLSX template import and export do not themselves call the server and remain free. Optimal packing, animation and result export do send necessary scene data; the preceding table describes how raw request details, the memory cache, usage records and result-export audit metadata are handled and retained.
If we need to collect anything outside the table, we will update this policy first and ask for consent again where the law requires it, rather than quietly start collecting it.
Your data is stored in Hong Kong, China (cross-border transfer)
This is the section to pay attention to, and the reason sign-in asks for a separate tick — under Chinese law, consent to a cross-border transfer cannot be bundled into a single "I agree to all of the above".
Why Hong Kong
There is one deployment. The server sits in the Hong Kong Special Administrative Region of China, and users inside and outside mainland China connect to the same machine. Latency from both sides is acceptable there, and a single deployment lets us spend our limited time on the product rather than on operations.
What this means for you: your personal information leaves mainland China and is stored on a server in Hong Kong. Under the Personal Information Protection Law, that is a provision of personal information outside the borders — for the purposes of that law, the Hong Kong SAR counts as outside.
Who the overseas recipient is
- Recipient
- 罗智予(个人) — the operator of this service in person (Individual developer, not a company), personally renting and administering the server
- Location
- Hong Kong Special Administrative Region, China
- Contact
- WeChat whatsmyweixinid · Email l2539527429@gmail.com
- Purpose of processing
- Providing registration and sign-in, accounting for free and paid entitlements, processing orders and manual payment verification, and computing or generating optimal packing, animation and result files
- Method of processing
- Handled by the server process; the table in this policy states whether each category is written to the database or enters memory cache, and for how long. Only the operator has access to the server
- Categories of information
- Phone number or email address, hashes of the session credential and optional password, IP address, usage and consent records, order, payment-verification and entitlement records, scene data needed for optimal packing, animation and result export, and related audit metadata
- Retention
- As set out in the table above
- Infrastructure provider
- 腾讯云 Tencent Cloud(中国香港地域) (server and bandwidth in the Hong Kong facility)
There is a second overseas destination: the United States. Email one-time codes are sent by Resend(Resend, Inc.,美国), a company based in the United States. That channel is switched on — if you register or sign in with an email address, the address you type is sent to that provider, which means your information reaches two overseas destinations, Hong Kong and the United States. Registering with a phone number does not go through it.
Consent comes before the code request: the sign-in checkbox names both the Hong Kong server and that “the email address will be sent to Resend in the United States to send the verification code.” The client requests a code only after the box is checked, and the server checks the current cross-border-consent field before calling either the email or SMS provider, so a direct API call cannot bypass it. A phone-code request does not send the phone number to Resend.
What you can do about it
- Don't tick the box if you don't agree. The app sends no request to the server and provides no offline exception for manual layout, templates or optimal packing; you can make a new choice later if you want to use it.
- Even before you sign in, the server sees your IP address when the page first checks account status. So the first time you open
/app/you are shown a cross-border notice: until you choose "Agree and continue", the page sends no request to the server at all; choose "Do not agree" and it sends none either and the service is not provided. We do not collect a device fingerprint; points are recorded only after sign-in and belong to the account. Your choice is stored in your own browser, and you will be asked again whenever the policy version changes. - If you are not willing to have personal information stored in Hong Kong at all, please don't use the service. That's the only honest answer we can give.
- You can withdraw consent on the current device at any time by deleting your account in the app on that device. Successful deletion immediately removes the cross-border consent stored by that browser, stops subsequent requests and shows the cross-border notice again; you must consent again before using the app next time. Consent stored locally by browsers on other devices is not remotely erased by this device. Withdrawal does not affect processing already carried out; historical usage, consent, order, payment-verification and entitlement records remain subject to the retention rules in section 02.
- You can ask us for a copy of your personal information, or ask us to delete it. See section 08.
Who else touches your information
We do not sell your personal information to anyone. But three kinds of provider are unavoidable in running the service. They process this information only within the scope we entrust to them, and may not use it for their own purposes:
- SMS code provider
阿里云计算有限公司「号码认证服务 · 短信认证」 - Sends and verifies sign-in codes for mainland China mobile numbers. They receive your phone number. The code is generated and checked by them; we never hold it.
- Email delivery provider
Resend(Resend, Inc.,美国) - Delivers the sign-in code to your mailbox. They receive your email address and the contents of that message.
- Server and network provider
腾讯云 Tencent Cloud(中国香港地域), Hong Kong, China - Provides the server, storage and bandwidth. The data physically lives in their facility.
Beyond these, we disclose your information only where the law requires it (for example a lawful request from a judicial authority), and we will tell you where we are permitted to.
Your rights, and how to exercise them
In relation to the personal information we hold about you, you may:
- Access and copy — ask for a copy of what we hold about you;
- Correct and complete — have us fix anything inaccurate;
- Delete — delete your account, or ask us to delete a specific item;
- Withdraw consent — including the separate consent you gave to storage in Hong Kong;
- Ask for an explanation of the processing rules described here;
- Port — where the statutory conditions are met, have your information transferred to another handler you designate.
How
- Delete your account: in the app, open the account menu at the top right → "Delete account". It asks for one more verification code, because the action is irreversible and an unattended keyboard shouldn't be able to destroy your account.
- Anything else: email l2539527429@gmail.com and we will respond within 15 working days. So that we don't hand your information to someone impersonating you, we may ask you to send that email from the phone number or address bound to the account.
What happens when you delete your account
- Your phone number / email is deleted from the database immediately and unbound, so it can be registered again (otherwise the right to deletion would be fiction);
- the account's password hash is cleared at the same time;
- every session is invalidated at once, on other devices too;
- the cross-border consent stored by the current device's browser is deleted immediately, subsequent requests stop and the cross-border notice is shown again; consent is required again on the next visit. Consent stored locally by browsers on other devices is not remotely erased;
- the account is marked deleted and can no longer sign in;
- historical usage and consent records, and order, payment-verification and entitlement records for completed activity, are retained as described in section 02. They are no longer linked to a phone number or email, but may retain the deleted account's ID.
If you believe our handling of your personal information breaks the law, please contact us first. You may also complain to the competent authority or bring a claim.
Minors
The service is aimed at logistics, freight forwarding and export professionals, not at children. We do not knowingly collect personal information from children under 14.
If you are a guardian and find that a child has registered without your consent, contact us and we will delete the information.
How we protect this information
- Everything is transported over HTTPS.
- Session credentials are stored only as hashes — someone who walks off with the database still cannot sign in as you.
- Optional passwords are stored only as salted scrypt hashes, never plaintext; the password hash is cleared when the account is deleted.
- Email codes are stored only as salted hashes, expire in 5 minutes, allow at most 5 attempts, and are rate-limited on sending.
- SMS codes are generated and verified by the SMS provider and are never stored by us.
- Points are bound only to the server account; we do not inspect canvas, fonts, graphics hardware, or other device traits to derive a fingerprint.
- The most effective measure is simply not collecting what we don't need. What we don't hold can't leak — we have no name, no ID number and no address for you.
No system is perfectly secure. If personal information is leaked, altered or lost, we will take remedial action immediately and notify you and the competent authority as the law requires.
Updates to this policy
We may update this policy. When we do, the version number and effective date at the top of this page change with it.
Every consent you give is recorded against a specific version. So if we change the purposes, the categories of information, the recipients or the cross-border arrangement, your old consent will not be treated as consent to the new version — we will ask again the next time you sign in, including asking again for the separate cross-border consent.
The Chinese version of this policy governs. This English version is provided for convenience; where the two differ in meaning, the Chinese version prevails.
Contact us
Any question, request or complaint about personal information goes here:
- Personal information handler
- 罗智予(个人)
- Contact email
- l2539527429@gmail.com
For matters about the service itself — point rules, disclaimers, disputes — see the Terms of Service.